9.3

CVSS4.0

CVE-2017-20202 - Web Developer for Chrome v0.4.9 Malicious Backdoor Supply Chain Compromise

Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, displayed fake “repair” alerts that redirected users to affili…

📅 Published: Oct. 8, 2025, 10:04 p.m. 🔄 Last Modified: Oct. 8, 2025, 10:04 p.m.

9.3

CVSS4.0

CVE-2017-20201 - CCleaner v5.33.6162 & CCleaner Cloud v1.07.3191 Malicious Backdoor Supply Chain Compromise

CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes an embedded blob into shellcode, allocates executable heap memory, resolves Windows API functio…

📅 Published: Oct. 8, 2025, 10:04 p.m. 🔄 Last Modified: Oct. 8, 2025, 10:04 p.m.

6.9

CVSS4.0

CVE-2025-11507 - PHPGurukul Beauty Parlour Management System search-invoices.php sql injection

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The exploit has been made a…

📅 Published: Oct. 8, 2025, 10:02 p.m. 🔄 Last Modified: Oct. 8, 2025, 10:02 p.m.

6.9

CVSS4.0

CVE-2025-11506 - PHPGurukul Beauty Parlour Management System search-appointment.php sql injection

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the argument searchdata results in sql injection. It is possible to launch the attack remotely. The expl…

📅 Published: Oct. 8, 2025, 9:32 p.m. 🔄 Last Modified: Oct. 8, 2025, 9:32 p.m.

6.9

CVSS4.0

CVE-2025-11505 - PHPGurukul Beauty Parlour Management System new-appointment.php sql injection

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/new-appointment.php. The manipulation of the argument delid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available…

📅 Published: Oct. 8, 2025, 9:32 p.m. 🔄 Last Modified: Oct. 8, 2025, 9:32 p.m.

6.9

CVSS4.0

CVE-2025-11503 - PHPGurukul Beauty Parlour Management System manage-services.php sql injection

A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been…

📅 Published: Oct. 8, 2025, 8:02 p.m. 🔄 Last Modified: Oct. 8, 2025, 8:02 p.m.

4.8

CVSS4.0

CVE-2025-11495 - GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly discl…

📅 Published: Oct. 8, 2025, 8:02 p.m. 🔄 Last Modified: Oct. 8, 2025, 8:02 p.m.

4.8

CVSS4.0

CVE-2025-11494 - GNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used…

📅 Published: Oct. 8, 2025, 7:32 p.m. 🔄 Last Modified: Oct. 8, 2025, 7:32 p.m.

5.3

CVSS4.0

CVE-2025-11491 - wonderwhy-er DesktopCommanderMCP command-manager.ts CommandManager os command injection

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been made publ…

📅 Published: Oct. 8, 2025, 7:02 p.m. 🔄 Last Modified: Oct. 8, 2025, 7:02 p.m.

5.3

CVSS4.0

CVE-2025-11490 - wonderwhy-er DesktopCommanderMCP Absolute Path command-manager.ts extractBaseCommand os command inj…

A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute Path Handler. Such manipulation leads to os command injection. The attack may be performed from remot…

📅 Published: Oct. 8, 2025, 6:32 p.m. 🔄 Last Modified: Oct. 8, 2025, 6:32 p.m.
Total resulsts: 313373
Page 2 of 31,338
« previous page » next page
Filters